UNC215 is a Chinese state-sponsored threat actor known for targeting global government, defense, and finance sectors.
Analyst brief
UNC215 is a Chinese state-sponsored threat actor active since at least 2014, targeting government, defense, technology, finance, and healthcare sectors globally, with a particular focus on the Middle East, Europe, Asia, and North America. Their key TTPs include using Mimikatz, FOCUSFJORD, and HYPERBRO for initial access and post-compromise activities, alongside evasion tactics like planting false flags and minimizing forensic evidence. Defenders should monitor for abuse of trusted third parties and implement detection rules for these specific tools and associated network anomalies.
UNC215
unknown
UNC215 is a Chinese nation-state threat actor that has been active since at least 2014. They have targeted organizations in various sectors, including government, technology, telecommunications, defense, finance, entertainment, and healthcare. UNC215 has been observed using tools such as Mimikatz, FOCUSFJORD, and HYPERBRO for initial access and post-compromise activities. They have demonstrated a focus on evading detection and have employed tactics such as using trusted third parties, minimizing forensic evidence, and incorporating false flags. UNC215's targets are located globally, with a particular focus on the Middle East, Europe, Asia, and North America.